Repository navigation
Conversation
The agent-skills generator was behind the code. Three provider routes gained a loopback-only note in the audit for the credential-validation spawn, and the generated endpoints reference never picked it up, so the skills sync check failed on the release branch. Signed-off-by: Minxi Hou <houminxi@gmail.com>
audit:deps fails the lint job on a critical advisory, not on the high ones. Those high findings are warnings. The critical one is next 16.3.5, inside >=16.2.0 <16.3.6, the ImageResponse RCE in next/og. 16.3.8 is the fixed release on the same 16.3 line. fumadocs-core accepts next 16.x. Nothing in this repo imports next/og. The lockfile moves only next and the @next packages it ships. Signed-off-by: Minxi Hou <houminxi@gmail.com>
This was referenced Oct 5, 2026
fix(quality): allowlist the check-workflows assert reduction from #14497 fail-closed refactor
#15575
Merged
Owner
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
release/v3.8.52. Three provider routes (/api/providers/validate,/api/providers/bulk,/api/providers/import) carry a loopback-only note from the credential-validation spawn audit, but the generatedskills/omni-providers/references/endpoints.mdnever picked it up.check:agent-skills-syncnow exits clean, which clears the "Merge integrity (changelog + generated skills)" failure that every PR into this release branch inherits.nextmoves from16.3.5to16.3.8. The lint job'saudit:depsstep fails on critical advisories. The critical one on this branch isnext>=16.2.0 <16.3.6(remote code execution innext/ogImageResponse).16.3.8is the fixed release on the same 16.3 line. High advisories such as@grpc/grpc-jsandaxiosstay warnings in that script and are not what fails the job.Related Issues
Validation
node --import tsx/esm scripts/skills/generate-agent-skills.mjsexits 0 after the change (dry-run reports nothing left to generate)npm audit --audit-level=criticalreports no critical advisories after installingnext@16.3.8npm run audit:depsexits 0npm run typecheck:corepassesfumadocs-core@16.15.4peers onnext@16.x.xrelease/v3.8.52@23a1148486Tests Added Or Updated
Coverage Notes
Reviewer Notes
release/v3.8.52checkout.next16.3.5to16.3.8plus the@next/envand@next/swc-*packages that release ships. No other dependency moved.next/og. The advisory is in the dependency itself.